Hackers Exploit macOS and iOS Vulnerabilities, CISA Issues Urgent Security Alert

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a severe warning about three actively exploited vulnerabilities targeting Apple platforms.

On March 5, 2026, these flaws were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling urgent action for both government and private sector network defenders.

According to CISA, the vulnerabilities affect a wide range of Apple devices running iOS, iPadOS, macOS, watchOS, and tvOS, as well as the Safari browser.

Federal agencies and organizations have been directed to apply vendor patches and mitigations no later than March 26, 2026, under the Binding Operational Directive (BOD) 22-01.

This addition emphasizes that threat actors are actively exploiting the vulnerabilities in ongoing cyberattacks.

Details of the Exploited Flaws

The first flaw, CVE-2023-43000, is a Use-After-Free (UAF) vulnerability found in macOS, iOS, iPadOS, and Safari 16.6.

This issue arises when a program continues to access freed memory, which can lead to memory corruption.

Attackers can exploit this weakness by luring victims to maliciously crafted web pages, which can result in system crashes or enable deeper compromise of user devices.

The second issue, CVE-2021-30952, involves an integer overflow vulnerability present across multiple Apple platforms, including tvOS and watchOS.

This flaw can also be triggered by malicious web content and could allow attackers to execute arbitrary code.

In practice, this means a remote adversary could run unauthorized commands and gain control over affected devices without user awareness.

The third vulnerability, CVE-2023-41974, is another Use-After-Free bug that targets iOS and iPadOS specifically.

Unlike the browser-based attack vectors of the other two, this one can be exploited by a malicious application installed on the device.

Once abused, it may allow arbitrary code execution with elevated kernel privileges, granting attackers deep-level access to the operating system and sensitive user data.

The inclusion of these vulnerabilities in CISA’s KEV catalog confirms they are under active exploitation in the wild.

While it remains unclear if these are linked to organized ransomware or espionage operations, CISA has labeled them as critical patching priorities.

System administrators and security teams are urged to immediately apply Apple’s latest updates, review vendor advisories, and implement continuous endpoint monitoring.

Individuals using Apple products should update their devices without delay to mitigate potential risks.

CISA’s KEV catalog entry lists these vulnerabilities as confirmed attack vectors, stressing swift compliance across all systems before the March 26 deadline.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories